cbcvebase.

Fortinet Forticlient vulnerabilities

84 known vulnerabilities affecting fortinet/forticlient.

Total CVEs
84
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH54MEDIUM25LOW4

Vulnerabilities

Page 3 of 5
CVE-2021-41028P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.0.9≥ 6.2.0, ≤ 6.2.9+3 more2021-12-16
CVE-2021-41028 [HIGH] CWE-295 CVE-2021-41028: A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0 A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and below may allow an unauthenticated and network adjacent attacker to perfor
nvd
CVE-2018-9193P3HIGHCVSS 7.8≤ 6.0.42019-05-30
CVE-2018-9193 [HIGH] CVE-2018-9193: A researcher has disclosed several vulnerabilities against FortiClient for Windows version 6.0.5 and A researcher has disclosed several vulnerabilities against FortiClient for Windows version 6.0.5 and below, version 5.6.6, the combination of these vulnerabilities can turn into an exploit chain, which allows a user to gain system privileges on Microsoft Windows.
nvd
CVE-2018-9191P3HIGHCVSS 7.8≤ 6.0.42019-05-30
CVE-2018-9191 [HIGH] CVE-2018-9191: A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attackers A local privilege escalation in Fortinet FortiClient for Windows 6.0.4 and earlier allows attackers to execute unauthorized code or commands via the named pipe responsible for Forticlient updates.
nvd
CVE-2025-57716P3HIGHCVSS 7.3≥ 7.0.0, < 7.2.12≥ 7.4.0, < 7.4.42025-10-14
CVE-2025-57716 [HIGH] CWE-427 CVE-2025-57716: An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4 An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may allow a local low privileged user to perform a DLL hijacking attack via placing a malicious DLL to the FortiClient Online Installer installation folder.
nvd
CVE-2019-17652P3MEDIUMCVSS 6.5≤ 6.2.12020-02-06
CVE-2019-17652 [MEDIUM] CWE-787 CVE-2019-17652: A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to cause FortiClient processes running under root priviledge crashes via sending specially crafted "StartAvCustomScan" type IPC client requests to the fctsched process due the argv data not been well sanitized.
nvd
CVE-2015-4077P4LOWCVSS 2.1PoC≤ 5.2.32015-09-03
CVE-2015-4077 [LOW] CWE-200 CVE-2015-4077: The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fo The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to read arbitrary kernel memory via a 0x22608C ioctl call.
nvd
CVE-2020-9291P3HIGHCVSS 7.8≤ 6.0.9≥ 6.2.0, ≤ 6.2.12020-06-01
CVE-2020-9291 [HIGH] CWE-668 CVE-2020-9291: An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a loca An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting the pool of temporary file names combined with a symbolic link attack.
nvd
CVE-2025-62676P3HIGHCVSS 7.1≥ 7.0.0, < 7.2.13≥ 7.4.0, < 7.4.52026-02-10
CVE-2025-62676 [HIGH] CWE-59 CVE-2025-62676: An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerabili An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.4, FortiClientWindows 7.2.0 through 7.2.12, FortiClientWindows 7.0 all versions may allow a local low-privilege attacker to perform an arbitrary file write with elevated permissions via crafted named pi
nvd
CVE-2019-6692P4HIGHCVSS 7.8≤ 6.2.02019-10-24
CVE-2019-6692 [HIGH] CWE-427 CVE-2019-6692: A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a p A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker to perform arbitrary code execution via forging that DLL.
nvd
CVE-2023-41840P4HIGHCVSS 7.8v7.0.9v7.2.0+1 more2023-11-14
CVE-2023-41840 [HIGH] CWE-426 CVE-2023-41840: A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to per A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path.
nvd
CVE-2019-16155P4HIGHCVSS 7.1≤ 6.2.12020-02-07
CVE-2019-16155 [HIGH] CVE-2019-16155: A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to overwrite system files as root with arbitrary content through system backup file via specially crafted "BackupConfig" type IPC client requests to the fctsched process. Further more, FortiClient for Linux 6.2.2 and below allow low privilege user
nvd
CVE-2024-54019P4MEDIUMCVSS 6.5≥ 7.0.0, < 7.2.7v7.4.02025-06-10
CVE-2024-54019 [MEDIUM] CWE-297 CVE-2024-54019: A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0 A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection.
nvd
CVE-2020-9290P4HIGHCVSS 7.8≤ 6.2.32020-03-15
CVE-2020-9290 [HIGH] CWE-427 CVE-2020-9290: An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library DLL files in that directory.
nvd
CVE-2021-32592P4HIGHCVSS 7.8≥ 6.0.0, ≤ 6.0.9≥ 6.2.0, ≤ 6.2.9+2 more2021-12-01
CVE-2021-32592 [HIGH] CWE-427 CVE-2021-32592: An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and F An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devices via a malicious OpenSSL engine library in the search path.
nvd
CVE-2022-45856P4MEDIUMCVSS 5.9≥ 5.0, < 7.2.1≥ 6.4, < 7.2.5+2 more2024-09-10
CVE-2022-45856 [MEDIUM] CWE-295 CVE-2022-45856: An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7 An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientLinux 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientAndroid 6.4 all versions, 7.0 all versions, 7.2.0 and FortiClientiOS 5.6 a
nvd
CVE-2022-26113P4HIGHCVSS 7.1≥ 6.0.0, ≤ 6.0.10≥ 6.2.0, ≤ 6.2.9+2 more2022-07-19
CVE-2022-26113 [HIGH] CWE-269 CVE-2022-26113: An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9, 6.0.0 through 6.0.10 may allow a local attacker to perform an arbitrary file write on the system.
nvd
CVE-2019-16152P4MEDIUMCVSS 6.5≤ 6.2.12020-02-06
CVE-2019-16152 [MEDIUM] CWE-20 CVE-2019-16152: A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user w A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to cause FortiClient processes running under root privilege crashes via sending specially crafted IPC client requests to the fctsched process due the nanomsg not been correctly validated.
nvd
CVE-2018-9195P4MEDIUMCVSS 5.9≤ 6.0.6≤ 6.2.12019-11-21
CVE-2018-9195 [MEDIUM] CWE-798 CVE-2018-9195: Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a M Use of a hardcoded cryptographic key in the FortiGuard services communication protocol may allow a Man in the middle with knowledge of the key to eavesdrop on and modify information (URL/SPAM services in FortiOS 5.6, and URL/SPAM/AV services in FortiOS 6.0.; URL rating in FortiClient) sent and received from Fortiguard severs by decrypting these messag
nvd
CVE-2015-5735P4HIGHCVSS 7.2≤ 5.2.32015-09-03
CVE-2015-5735 [HIGH] CWE-264 CVE-2015-5735: The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fo The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to write to arbitrary memory locations via a 0x226108 ioctl call.
nvd
CVE-2009-1262P4HIGHCVSS 7.2v3.0.6142009-04-07
CVE-2009-1262 [HIGH] CWE-134 CVE-2009-1262: Format string vulnerability in Fortinet FortiClient 3.0.614, and possibly earlier, allows local user Format string vulnerability in Fortinet FortiClient 3.0.614, and possibly earlier, allows local users to execute arbitrary code via format string specifiers in the VPN connection name.
nvd
Fortinet Forticlient vulnerabilities | cvebase